Thursday May 17

Archive for 2010

Nov
29/10
Security School: Using IDS and IPS to meet business objectives
Last Updated on Monday, 29 November 2010 02:00
Written by jj
Monday, November 29th, 2010

Hey everyone! Long time no see. I’m working up some recaps from Deep Sec in Vienna as well as a few 802.1X-2010 updates. In the meantime…

As promised, I’m letting you know about content I’ve done for Tech Target’s SearchSecurity site (publishers of Information Security Magazine).

Below is a link to the Security School I authored titled ”Using IDS and IPS to meet business objectives“. Included in this Security School is the usual video, podcast and tech tip with BONUS quiz. w00t. We all love quizzes, don’t we? You might already know the answers to the questions; if not they’re all contained in the various parts of the school, if you can muddle through listening to my Southern accent for 15-20 minutes. Despite daily refutes, I keep telling myself I don’t have an accent. Apparently, I’m wrong.

Tech Target’s SearchSecurity.com
Security School: Using IDS and IPS to meet business objectives
http://searchsecurity.techtarget.com/guide/securitySchool/category/0,296296,sid14_tax317100,00.html

VIDEO – Meeting business goals with network security technologies
This video will discuss how moving from primary business functions to more detailed business tasks can help identify goals that network security can assist in meeting. 

PODCAST- Countdown: Top 5 ways to tune IDS/IPS to meet business needs
In this podcast, we’ll count down the top five ways to tune an IDS/IPS to make sure it’s meeting the business requirements you purchased it to meet. 

TECH TIP- IDS vs. IPS: How to know when you need the technology
IDS and IPS are useful security technologies, but how do you know whether your enterprise can benefit from one? In this tip, infosec pro Jennifer Jabbusch offers a few specific use cases to help you know when to consider… 

QUIZ: How IDS/IPS can enable business objectives
How much have you learned about integrating IDS/IPS with your enterprise’s business goals? Find out with this short quiz.

# # #

Tags: , , ,   |  Posted under Uncategorized  |  Comments  No Comments
Nov
21/10
Coming to Deep Sec next week “Identicate & Authentify”
Last Updated on Tuesday, 31 January 2012 05:45
Written by jj
Sunday, November 21st, 2010

This coming Thursday (Thanksgiving here in the US) I’ll be speaking at the Deep Sec Conference  in Vienna. I’m extremely excited and at the same time, nervous, to be presenting a new topic to a new audience. (more…)

Tags: , , ,   |  Posted under Events  |  Comments  1 Comment
Nov
19/10
Conversation with Jennifer Jabbusch on NAC [VPN Haus]
Last Updated on Saturday, 28 January 2012 06:28
Written by jj
Friday, November 19th, 2010

I didn’t post this originally because I was waiting for Part 2 to be released. I know you people; no one wants to read the first half of something and then have to revisit it later for a second part. In my quest to provide both pieces for you, I somehow missed Part 2. I’ll blame it on travel for work and the gov conference at which I was speaking during that week. Yeah, that sounds good – we’ll go with that.

In any event, several people seemed to like the Q&A session I responded to with the team at VPN Haus. You can read the exchange on their blog.

No Mike, NAC’s not dead. We’re still talking about it – see?

Conversation with *me* on NAC at VPN Haus

# # #

Posted under Industry Insider, Uncategorized  |  Comments  No Comments
Nov
03/10
An SMB Guide to Credit Card Regulations: Part II- The Low-Hanging Fruit- Networks and Users [Dark Reading]
Last Updated on Wednesday, 3 November 2010 10:04
Written by jj
Wednesday, November 3rd, 2010

The PCI Security Standards Council has created a document outlining a prioritized approach to help businesses comply with PCI DSS. It’s a way to grab the low-hanging fruit, helping businesses tackle some of the more simple tasks that can provide a greater security ROI. I’ve boiled it down here to help small to midsize businesses get started.The official document is about 15 pages of an organized chart, outlining tasks and subtasks as they relate to the PCI DSS requirements and the six primary milestones of the Prioritized Approach document. Those six milestones and goals are:

1: Remove sensitive data and limit data retention
2: Protect the networks
3: Secure payment card software applications
4: Monitor and control access to your systems
5: Protect stored cardholder data
6: Finalize remaining compliance efforts, and ensure controls are in place to meet the rest of the PCI DSS requirements.

Instead of regurgitating the dozen or so pages of itemized tasks, I thought it would be more useful to identify a set of specific tasks for small businesses to address, by category. Each task relates to one or more milestones in the Prioritized Approach and helps achieve one or more of the PCI DSS requirements.

 

Read the entire article at Dark Reading
http://darkreading.com/blog/archives/2010/11/an_smb_guide_to.html

# # #

Tags: , ,   |  Posted under SMB, White Papers & Guides  |  Comments  No Comments
Oct
21/10
An SMB Guide to Credit Card Regulations: Part I- PCI DSS Q&A [Dark Reading]
Last Updated on Thursday, 21 October 2010 01:54
Written by jj
Thursday, October 21st, 2010

This article is the first in a short series designed to help small businesses understand the regulations around securing credit card transactions, specifically the PCI DSS (Payment Card Industry’s Data Security Standard) requirements.

In an effort to provide the most tangible information, I’ve consulted with a Qualified Security Assessor (QSA). Portions of content and resources in this series have been contributed by trusted security colleague, Martin McKeay, QSA and host of the Network Security Podcast.

Let’s jump right in and start looking at some of the most intriguing questions surrounding the PCI DSS requirements, as they apply to smaller businesses.

Read the entire article at Dark Reading
http://darkreading.com/blog/archives/2010/10/what_every_smal.html

# # #

Tags: , ,   |  Posted under SMB  |  Comments  No Comments

More Content

Find more of my content at
- Low Tech Hacking book
- Dark Reading
- Network Computing
- IANS
- SearchSecurity
- TechTarget

Get Social

RSSFacebookLinkedinYoutube